Honest Comparison

Gatez vs Portkey

Portkey is a best-in-class AI gateway for multi-model routing and prompt engineering. Gatez is a unified, fully self-hosted L1+L2+L3 platform for regulated teams.

Portkey

A best-in-class AI gateway for multi-model LLM routing — 1,600+ models across 40+ providers with observability, guardrails, caching, and a mature prompt-management studio. Now part of Palo Alto Networks (Prisma AIRS) as of 2026.

SaaS-first, with an open-source gateway proxy and an enterprise hybrid option. Governs LLM traffic — not your general API estate — and adds MCP plus basic agent proxying.

Gatez

A three-layer unified gateway (L1 API + L2 AI + L3 Agent) with multi-tenant governance, built for platform teams who must manage APIs, LLM calls, and agents in one self-hosted control plane.

Combines APISIX, a custom Rust AI Gateway, and a custom Rust Agent Gateway with tenant isolation, per-hop agent identity, and a customer-owned audit trail — fully on-prem, air-gap capable.

Feature Comparison

Feature Portkey Gatez
Gateway Layers
API Gateway (L1) — general API traffic LLM-only APISIX
AI Gateway (L2) Rust
Agent Gateway (L3) ~ basic Rust
AI Features
Multi-model routing 1,600+ models 13 providers
Semantic caching ~ Pro / Enterprise Redis + Qdrant, on-prem
PII redaction (pre-LLM) partner-based Presidio, local
Per-tenant token budgets ~ Enterprise-only per-tenant
Prompt management / versioning Prompt Studio
Local / on-prem LLM (Ollama) custom host
Multi-tenancy & Governance
Infrastructure-level tenant isolation ~ workspace RBAC tenant_id through every layer
Per-tenant rate limiting ~ virtual-key limits Redis sliding window
HITL approval gates blog concept first-class queue
Tool allowlists ~ tool RBAC deny-by-default
Agent Features
MCP Protocol
A2A Protocol ~ proxy + RBAC policy-governed
Per-hop agent identity (RFC 8693) token exchange, delegation chain
A2A delegation policies + loop detection cross-tenant block, depth limit
A2A topology visualization
Observability & Compliance
Customer-owned audit store SaaS-hosted logs ClickHouse on-prem
Log retention control ~ 3–30d; custom = Enterprise you set the TTL
Cross-layer tracing (L1→L2→L3) no L1 one OTel trace
Usage analytics SaaS dashboards ClickHouse dashboards
Operator + Developer portals ~ SaaS dashboard two self-hosted portals
Deployment & Governance
Fully on-prem (control plane included) ~ hybrid: SaaS control plane
Air-gapped deployment ~ Enterprise custom out of the box
No external phone-home hybrid re-syncs to SaaS
Ownership Palo Alto Networks Independent

full support  ·  ~ partial / tier-gated  ·  not available. Portkey capabilities as of mid-2026; verify current tiers on portkey.ai.

Where Portkey Leads

  • LLM provider breadth: 1,600+ models across 40+ providers through one API — materially ahead of Gatez's 13-provider L2
  • Prompt Engineering Studio: versioning, publish/rollback, multi-model A/B testing and a playground — a workflow Gatez does not have
  • SaaS onboarding speed: three lines of code, free tier, no infrastructure — a developer can be in production in minutes
  • Production pedigree: 1T+ tokens/day across 24,000+ organizations — a deep reference base for enterprise evaluations
  • Guardrail & framework ecosystem: 50+ partner guardrails and native SDK hooks for LangGraph, CrewAI, and the OpenAI Agents SDK
  • Palo Alto Networks backing: for teams already on Prisma / Cortex, integration into the PANW security stack can be a procurement shortcut

Where Gatez Leads

  • Unified L1+L2+L3: one control plane for your general API estate (APISIX), LLM calls, and agents — Portkey governs LLM traffic only and cannot replace your API gateway
  • True full on-prem: the entire stack — portals, ClickHouse, Redis, OTel — runs in your network with no phone-home, even in air-gapped environments
  • Customer-owned audit store: ClickHouse runs in your environment — you own the data and set retention, with no dependency on a vendor's infrastructure
  • Per-hop agent identity (RFC 8693): every delegation hop carries a cryptographically verifiable chain — who, acting as whom, for whom — enforced at the gateway. No competitor ships this today
  • Gateway-enforced HITL: tool execution is blocked at L3 and routed to a first-class approval queue in both portals — not delegated to the application
  • Infrastructure-level multi-tenancy: tenant_id flows through APISIX rate-limit buckets, Redis keyspaces, and ClickHouse row filters — provable isolation, not just RBAC
  • Vendor independence: Gatez is not owned by a $100B security vendor — no PANW roadmap or procurement dependency in your AI stack

When to Choose Which

Choose Portkey when:

  • Your primary need is multi-LLM routing across the broadest possible model catalog, without strict data-residency requirements
  • Your team iterates heavily on prompts and needs production-grade prompt versioning and A/B testing
  • You want SaaS onboarding speed with no infrastructure to run
  • You're already a Palo Alto Networks / Prisma customer and want it in your existing agreement
  • Your agent use case is LLM observability and cost governance — not gateway-enforced HITL or per-hop identity
  • You're a startup or mid-market team without an on-prem or air-gap requirement

Choose Gatez when:

  • You're in a regulated environment (banking, healthcare, government, defense) where all data must stay in your infrastructure
  • You need one control plane for your API estate + AI + agents — Portkey can't replace your API gateway
  • You require provable infrastructure-level tenant isolation, not application-layer access control
  • You're deploying air-gapped, where even a SaaS control plane is unacceptable
  • You need gateway-enforced HITL and per-hop RFC 8693 agent identity for auditable multi-agent workflows
  • Your audit trail must live in a database you own, with retention you control

Ready to try Gatez?

Request a demo to explore gatez features.